In April 2026, the conversation about agentic sovereignty stopped being a debate and became a market with formal commercial offerings. Three distinct types of proposal — all legitimate, all selling right now — are being blended in the Spanish and European discourse under the same label. For a CIO reading RFPs, telling them apart is non-trivial, and the operational consequence of failing to do so is measured in years of lock-in.
What follows is an operational framework: a split of control across eight axes that any CTO can run over their next agentic project next week.
Why the question about sovereign AI changed in April 2026
Until March, "sovereign AI" was an awkward conversation. Europe's defense of the past decade had produced three correct but abstract arguments — data residency, sovereign hardware, open models — without any of them quite crystallizing into a buyable offering. In April it crystallized. A Spanish industrial group commercially launched its AI and cyber-defense subsidiary with public figures in the order of €300 million and more than five declared client deployments. A European integrator simultaneously presented a combined offering of sovereign agentic studios and integrated digital sovereignty, aimed at public administration and regulated sectors. And on the first day of May, Microsoft announced the general availability of Agent 365 within a new Microsoft 365 E7 license tier, at a bundle price of $99 per user per month.
The consequence is that any IBEX (Spain's blue-chip index) or mid-cap buyer opening an agentic RFP in May or June is going to receive three types of response that call themselves sovereign. All three are, in different senses. And precisely because all three use the same word, the right question isn't which of the three is more sovereign — it's which of the three answers your operational definition of sovereignty. To answer that, you first have to separate the three concepts.
Three concepts that get mixed: infrastructure, stack governance and operation
Infrastructure sovereignty
Where are the bytes? Residency, jurisdiction, hardware, models.
The classic European reading. Real traction in regulated banking, defense, healthcare, public administration. onext does not solve that question.
Vendor-stack governance
The agentic layer integrated with the identity, data and security you already have under contract.
Solid if you live in M365 (Entra · Purview · Defender · Copilot Studio). The price of coherence is the boundary of the walled garden.
Infrastructure sovereignty is concerned with where the bytes are: geographic residency, the cloud provider's jurisdiction, European-manufactured hardware where applicable, models trained in given territories. The offering of the Spanish industrial sovereign-AI brand and that of the European integrator live on this axis. They are serious, articulated proposals, with clients in production. If your requirement is data residency on Spanish or European soil under the control of a group with proven deployment capability, that question has a clear answer.
Vendor-stack governance is what Microsoft Agent 365 articulates: the agentic layer (agent discovery, authorization, auditing, policy enforcement, data loss prevention) integrated with the identity, data and security plane you already have under contract. It's a solid proposal if the client's stack is predominantly Microsoft. What happens inside the walled garden is well governed; what happens outside — a Claude agent, a local open-source model, a pipeline on Bedrock, an integration with non-Microsoft SAP — lives with a different control logic and a different audit surface.
The third concept is what at onext we call operational sovereignty, and it's the one most RFPs still don't name explicitly. The question isn't where the bytes are or which hyperscaler hosts them. It's who decides what can read them, at what moment, under what rules, and who gets notified of the result. The difference is operational, not geographic: two clients with data in the same European data center can have radically different levels of control over what an agent can do with them. Operational sovereignty either materializes or it doesn't across eight concrete axes.
The rest of the stack closed in 30 days: five FDE-embed coalitions with the seven largest integrators
The decision we signed in April assumed that the consolidation of the agentic stack would take two or three quarters to set. It took five weeks. Between April 25 and May 21, the six largest agentic platforms — Microsoft, ServiceNow, Anthropic, Salesforce, OpenAI and Google — have signed structural FDE-embed coalitions with the seven largest global integrators. Salesforce launched its FDE Network on Apr 25. ServiceNow and Accenture launched their Forward Deployed Engineering Program on May 6. OpenAI formalized its Deployment Company on May 11, integrating Tomoro as an embedded practice and taking equity in Capgemini, Bain and McKinsey. KPMG and Anthropic signed on May 19. And on May 21, EY and Microsoft announced a joint $1 billion investment over five years to embed Microsoft AI-native Hypervelocity Engineering FDEs inside the EY consulting practice, presenting EY as "Client Zero" with 150,000 Copilot users and a reported 15% increase in productivity.
What matters about this sequence isn't any of the individual signatures — it's the pattern. In 30 days, enterprise operational consolidation is complete for IBEX companies. Any IBEX company opening an agentic RFP in June or July is going to receive proposals where the team deciding its agentic architecture answers to a vendor matrix — Seattle, Bangalore, Dublin or central Madrid — different from its Board. That's legitimate, and for many organizations it's exactly what they need. But the operational consequence for a Spanish company of 100 to 1,000 employees is different from the consequence for Iberdrola or Banco Santander, and it's worth naming: none of the five FDE-embed coalitions is built for the mid-market. Accenture's FDE program doesn't parachute into a Spanish mid-sized company. Neither does KPMG-Anthropic's. That's the category of client for which the architectural decision of the eight-axis split weighs more, not less.
The eight operational axes of the split of control
Operational sovereignty isn't an abstraction: it either materializes or not across eight concrete axes, each with a canonical question a CTO can ask without ambiguity and a vendor can answer without escape.
1. Identity: how agents, users and services are federated
Who is the agent executing the action, who is the human user triggering it, who is the originating service, which identity provider federates all of that, and what happens when the agent has to talk to a system whose IdP is different from yours. The canonical question is: if I switch IdP tomorrow, how many weeks until my agents keep working?
2. Data: residency, ACL, retention and deletion
Residency, access control lists, retention policy, deletion policy. What matters operationally isn't where the data is — that's the first concept, infrastructure — but who decides which retention applies to a specific data point when an agent reads it, and who signs the export operation when it needs to leave its place.
3. Model: is switching LLM a weekly decision or a migration project?
Which LLM or SLM runs each use case, on which provider, with what fallback. The operational question is whether switching the model is a weekly decision — because a better, cheaper, more use-case-aligned one comes out — or a three-month migration project. When an agent lives hooked to a single model provider, sovereignty over the model has been ceded.
4. Context: the layer that defines your competitive advantage
The most important one for the onext argument. It's the client-specific curated data layer — documented relationships between domain concepts, operational instructions that encode how the organization decides, retrieval policies, cost-per-request contracts. Context is what makes a corporate-banking support agent you sell to one bank not interchangeable with the one you sell to another. It's the client's property by definition — or it should be. In proposals that treat context as a fuzzy layer integrated with the cognitive one, or as the vendor's property, this axis gets ceded without the buyer noticing.
5. Agent: open runtime or captive to the Marketplace?
The runtime, the communication protocol between agents, the ability to orchestrate pieces that live in different stacks. The operational question is whether your agentic plane speaks MCP, A2A or some open equivalent, or whether it lives captive in a specific Marketplace's catalog.
"Agent orchestration — context management, error handling, and the actual agent loop — stays on Anthropic's infrastructure. A fully on-premise deployment of the agents isn't possible."
— Anthropic, Code with Claude London, May 19, 2026.
This quote isn't our opinion: it's a public statement from the vendor that governs context best in the market in 2026. If Anthropic — the most honest of the tier-1 — needs to acknowledge that the agent's orchestration stays on its infrastructure, it's worth asking what the other vendors promise when they talk about "total sovereignty" without qualifying the scope. The fifth axis, read in May 2026, isn't an onext hypothesis about how runtime control is split: it's a constraint documented by the vendor itself with the most mature agentic proposal of the quarter. For the remaining seven axes, the documentary asymmetry with the competition is of the same order.
6. Logging: does your SIEM consume the traces, or the vendor's?
Traces, auditability, exportability. Who consumes the traces — your SIEM or the vendor's — determines whether your security team can investigate incidents with their own tools or depends on the support window the vendor offers you.
7. Human-review gates: human-on-the-loop by procedure
The well-known human-on-the-loop architecture is operational or decorative depending on who decides at which specific procedure the agent stops and waits for sign-off. In proposals with generic gates, the client ends up accepting the vendor's default matrix; in proposals with per-procedure gates, the client encodes its own.
8. Exit: on day 1,001, what do you take with you?
If on day 1,001 you decide to change provider, what do you take with you? Your data, yes — even the most captive of stacks gives you that. But do you take the rules, the policies, the cost contracts, the agents you've built on top, the episodic memories they've learned about your domain, the retrieval indexes that have indexed your corpus? If not, the lock-in is real even if the word "sovereign" appears in the contract.
Two readings of "sovereignty": national infrastructure and portable operation
Among the May FDE-embed signatures, there's one that directly affects the Spanish frame and is worth isolating. On May 20, during King Felipe VI of Spain's official visit to Canada, Indra Group signed an MoU with Cohere to jointly develop Spain–Canada sovereign AI solutions, implemented through IndraMind. The proposal includes native multi-language development — Spanish, Catalan, Valencian, Basque and Galician — an agentic platform aimed at SMEs, and an explicit defense use case. Added to Cohere's prior acquisition of Aleph Alpha on April 24 and the purchase of Reliant AI on May 19, Western sovereign has, in May 2026, five declared layers — Cohere, Aleph Alpha, IndraMind, Atos Sovereign Agentic Studios, Eviden ELIT AI — with an explicit bilateral institutional flag.
The editorial consequence forces us to separate two readings that in April could be left grouped. There's an infrastructure sovereignty at the national level — do the model and the hardware stay in my country? do they speak my language natively? does the vendor answer to a jurisdiction allied with mine? — that in May 2026 was defined in Spanish by IndraMind + Cohere with bilateral government backing. For public administration, defense, regulated banking with an explicit ENS High (Spain's National Security Framework, High level) requirement and sectors with vendor-stack sovereignty tender specs, that question has a clear answer and onext does not solve it. And there's a portable operational sovereignty — who operates the business logic the day the model, the provider or the jurisdiction changes? which architectural decision survives the vendor's rebrand, the pricing change or the renegotiation of the consultancy contract? — that remains onext territory in May and, foreseeably, over the next four quarters. The two readings are compatible. Most IBEX organizations are going to need both at once, in different proportions by sector. What they are not is equivalent or interchangeable.
Reading the matrix: each is a champion at something, none covers all eight
Applied to the four proposals active in the Spanish and European market in May 2026 — onext and the three archetypes described — the split of control ends up like this:
The reading that emerges from the matrix is the most useful one in the article: each proposal is a champion on at least one axis and none of the three alternatives covers all eight simultaneously. The industrial sovereign-AI brand is a champion on the data axis when the requirement is Spanish residency under the control of a group with deployment capability. The European integrator is a champion if you need a full EU sovereignty stack under a single contract. Microsoft Agent 365 is a champion if your organization lives predominantly in M365 and coherence with Entra, Purview and Defender is what weighs most in your evaluation.
What onext offers is full coverage of the eight axes with a common operational principle: control stays in the client's hands on each one of them. It's not a superior proposal axis by axis — on data, the industrial sovereign-AI brand may be equivalent or superior if your priority is Spanish residency; on logging within M365, Defender is the reference; on Microsoft agents, Agent 365 is better integrated. It's a superior proposal when the eight axes are evaluated together.
The map of the enterprise agentic stack in May 2026
It's worth closing the market context with an overview, because the decision about the eight axes is better understood when set against the vendor stack that has stabilized over the quarter. In May 2026, the control plane is formalized by the five layers that Google Cloud Next 2026 crystallized — runtime, identity, data, payments, observability — and that Bain & Company's analysis of May 13 endorsed as a stable tier-1 category. The studio layer has closed into five proposals — SAP Joule, IBM Context Studio, Databricks Agent Bricks, NTT SDI/WinWire, Microsoft Agent 365 with Salesforce Agentforce as the CRM-centric variant — and no relevant sixth studio has appeared in the last sixty days. The data plane has unified into a single neutral arbiter after the May 20 launch of Informatica MCP cross-vendor, which offers native headless data management simultaneously over Salesforce, Snowflake, Databricks, AWS and Microsoft Foundry. The Western sovereign layer has five declared vendors — Cohere, Aleph Alpha, IndraMind, Atos Sovereign, Eviden ELIT AI — with a bilateral Spain–Canada institutional flag. And the agentic defensive cyber-clustering layer has come together into two coalitions — CrowdStrike Project QuiltWorks and Zscaler AI-Guardian — in fourteen days.
Four layers, twelve vendors, five FDE-embed coalitions. What's missing from this map is the sixth layer: the client-retained operational business logic. Google doesn't cover it with its control plane, because Google is a runtime vendor. No studio covers it, because every studio is optimized to extend the vendor's own context. Informatica's data plane doesn't cover it, because Informatica is a neutral arbiter of raw data, not of the rules your organization applies on top. Western sovereign doesn't cover it, because Western sovereign is model residency and vendor sovereignty — not client-retained operation. And the FDE-embed coalitions don't cover it because their business model is exactly the opposite: the FDE lives in the client but answers to the vendor matrix. The sixth layer — the one that protects the buyer's architectural decision the day after the vendor changes — is precisely the one onext defines across the eight axes above.
When you need each one — and when you need onext
| If your RFP answers to… | The most efficient option is… |
|---|---|
| A regulatory mandate for Spanish residency, other axes solvable in a second layer | Industrial sovereign-AI brand · fastest to approve |
| A European public-administration program with a full EU sovereignty stack in the tender spec | EU sovereignty integrator · a single contract |
| A predominantly Microsoft base, where Entra-Purview-Defender coherence weighs more than cross-vendor openness | Microsoft Agent 365 · most efficient to procure |
| All eight axes weigh at once — SAP + Microsoft + Salesforce + Oracle, cloud + on-prem, closed models + open-source, own agents + third-party | onext · full split of control |
onext comes in when the eight axes weigh at once. When your organization has SAP as well as Microsoft, Salesforce as well as SAP, Oracle on top of the previous ones, data in public cloud and data on-prem, closed models and open-source models, own agents and third-party agents. In that heterogeneity — which is the real situation of most of the IBEX and the European mid-cap — the eight-axis split of control stops being a theoretical elaboration and becomes the only viable framework for keeping operational governance without giving up interoperability.
Sovereign Operating Firm: the onext category
There's a new frame circulating among Big4 and tier-1 platforms that's worth naming. On May 21, Microsoft and EY presented their $1 billion, five-year initiative under the Frontier Firm label: the company that operates with AI embedded end-to-end via Copilot, with Microsoft FDEs integrated into the EY practice deploying agentic capability inside the client. EY positions itself as "Client Zero" of the model. It's a legitimate, ambitious and executable proposal. Its name describes precisely what it is: the company's operational frontier is defined by the combination of vendor + Big4 + FDE.
The question any mid-market CIO or large IBEX account should ask before signing is complementary, not contrary, and it demands being named with the same clarity. There's a second category — the one onext defines and that we call Sovereign Operating Firm — that's built on the same end-to-end agentic principle but with the operational business logic retained on the client's side. The difference is operational, not ideological, and it's measured across three concrete axes.
The first axis is vendor portability. A Microsoft + EY Frontier Firm is optimized for the Microsoft stack and the EY methodology; switching stack or Big4 is an architectural decision that costs between eighteen and thirty months of migration. An onext Sovereign Operating Firm is built on the eight axes and explicitly designed so that switching model, vendor or jurisdiction is executed in weeks, not years. The second axis is business logic. In the Frontier Firm, the logic that triggers what the agent does lives in the EY practice and in the Microsoft FDEs. In the Sovereign Operating Firm, that logic is encoded as client-specific context engineering, lives in the client's team and is documented in artifacts the client owns — not in recurring consultant-hours. The third axis is the real cost of the agent. In the Frontier Firm, the agentic cost is diluted in the vendor + Big4 bundle billing. In the Sovereign Operating Firm, the cost per agent is visible monthly, governable by line of business and comparable across stacks. Anthropic has just inaugurated the first metered tier-1 pricing with its model of separate credits for Agent SDK, GitHub Actions and third-party frameworks, effective June 15: agentic economics is starting to become visible, and the Sovereign Operating Firm is the framework that lets you govern it without diluting control in enterprise billing.
The question a leadership team can take to its next meeting is, therefore, a single one, and it's formulated in one line: "do we want a company that operates better with our current vendor (Frontier Firm), or a company that is operationally sovereign of whichever vendor we decide on tomorrow (Sovereign Operating Firm)?" Both answers are legitimate and for many organizations the right answer is the first. But calling both by the same name — as has been happening throughout April and May under the generic label "sovereign AI" — confuses the decision and hides its operational consequences three years out. The eight-axis pillar piece is built so that decision gets made with judgment.
How to apply the split of control in your next agentic RFP
If this reading resonates and you're inside an evaluation process, the practical exercise we recommend is to read the matrix backwards. Take your next agentic RFP and, before asking vendors for answers, write on one page what color you want the cells to be — axis by axis — for each of the eight axes. The conversation with any provider, onext included, improves by an order of magnitude when the client brings the eight colors predefined instead of asking the vendor to self-classify.
If you want a second opinion on how the split applies to your specific case — which axes weigh most in your sector, which cells are non-negotiable and which you can afford in amber, or whether the Frontier Firm or Sovereign Operating Firm decision is the right one for your organization — the first forty-five minutes are on us, the decisions are yours. Across the twelve development teams we've transformed under this framework, the speed of getting to production multiplies by seven, time-to-production halves and no sprint has been lost during the transformation. But that's another conversation. Today's is simpler: don't let your next agentic RFP go out without the eight axes mapped — and without naming what kind of company you want to be when all of them are operational.
Dual signature: onext CEO with Head of AI Engineering · original piece 2026-05-05 · refresh 2026-05-25 incorporating the Sovereign Operating Firm frame and subsequent market context.
Sources and references: analysis of the Spanish and European sovereign AI market in April–May 2026; commercial launch of the AI and cyber-defense subsidiary of a Spanish industrial group (~€300M revenue, >5 client sites); combined offering of sovereign agentic studios + integrated digital sovereignty from a European integrator (launched April 28, 2026); GA of Microsoft Agent 365 within the Microsoft 365 E7 bundle ($99/user/month, announced May 1, 2026); onext's experience in multi-vendor agentic architecture with twelve transformed teams.
Further reading: Context engineering vs Agent Marketplace | 7 questions for your AI RFP | Make/buy and cost of exit in agent platforms | Five criteria for choosing an AI partner | Three canonical AI-dev claims · source of truth. And the previous piece articulates the headline metrics that underpin the Sovereign Operating Firm.
onext methodology: onext AI-Accelerated Development is the methodology with which we help mid-sized and large companies map the split of control across the eight axes from day one — with ownership and portability of context, identity and agents guaranteed by contract.

Jordi García is Tech Lead at onext. He works on bringing AI into governed production across development and product teams —with Spec-Driven Development, context engineering and human verification at every step— and authors onext's technical insights on the method, quality and cost of applied AI.
LinkedIn →